Cybersecurity programs

Security you can actually show someone.

Buying security products is easy and proves nothing. A program is the difference between hoping you are covered and being able to demonstrate it to an insurer, a client, a board or a regulator when they ask.

The form this is really about

Your insurance renewal has eleven questions on it this year.

Last year it had three. Now it wants to know whether every account uses multi-factor authentication, how often you test restores, whether staff get security training, and what your incident response plan says. Somebody has to tick those boxes, and ticking them wrongly is worse than not having the cover.

The same questions arrive from clients running vendor reviews, and from the bank, and eventually from whoever is buying your business. They are all asking the same thing: can you show us, rather than tell us.

The distinction that matters

Tools are not a program.

What most businesses have

  • Antivirus on the computers, probably
  • Multi-factor on some accounts, added in a hurry
  • Backups running, never tested
  • Training done once, two years ago
  • No idea which of these is the weak one

What a program adds

  • A written picture of where you actually stand
  • A plan with an order, so the biggest risk goes first
  • Evidence, kept current, for whoever asks
  • A rehearsed answer for the day something happens
  • Someone accountable for all of it

The products matter. They are just the easiest part, and the part every provider sells. What is usually missing is the structure around them.

Included, not extra

Most of this already comes with your agreement.

Security is not something we sell alongside fully managed and co-managed IT. It is part of both, running from the first month, and this is what that baseline covers.

Who can get in

  • Multi-factor authentication on every account that matters
  • A password manager for your staff, so they stop reusing one
  • Administrator accounts kept separate from everyday ones
  • Access reviewed, and leavers shut down the same day
  • Sign-ins from places your people are not, flagged

The machines

  • System updates and patching on a schedule, across every device
  • Protection on computers, servers and phones
  • Hard drives encrypted, so a lost laptop is not a lost database
  • Equipment past the end of support flagged before it is a problem
  • An inventory, so nothing is quietly unmanaged

Email and data

  • Filtering tuned to the scams aimed at your industry
  • Records set so nobody can convincingly impersonate your domain
  • Links and attachments checked before anyone opens them
  • Rules about where company information is allowed to go
  • Backup of your Microsoft 365 data, which Microsoft does not do

Your people

  • Short security training, repeated rather than done once
  • Phishing simulations, used to teach rather than to catch out
  • New starters set up correctly from their first morning
  • Somebody to ask when an email looks wrong, before clicking
  • Guidance written for staff, not for technicians

Watching it

  • Monitoring and alerting, so we usually know before you do
  • Logs kept, so questions can be answered after the fact
  • Regular scanning for known weaknesses
  • Backups tested, not just reported as successful
  • A plain-language summary at your review

The network

  • A business firewall, configured rather than plugged in
  • Guest and staff networks kept properly apart
  • Remote access that does not open a door to everyone
  • Wi-Fi secured, including the part nobody has looked at since 2019
  • Changes documented as they happen

Where the baseline comes from

We work from CIS and NIST rather than inventing a standard.

Two bodies of work do the heavy lifting. The CIS Controls are a prioritised list of safeguards, ordered by what actually prevents the most damage, and grouped so a small business can start at the first group and grow into the second. The NIST Cybersecurity Framework gives the structure a program hangs on: identify, protect, detect, respond, recover.

That matters to you for two practical reasons. It means the order we do things in is not our opinion, and it means when an insurer, a client or an auditor asks what you are working to, there is a real answer with a name on it rather than a description of our habits.

You will not be asked to read either document. That is our job.

  • CIS Controls, first group as the floor
  • The second group as you grow
  • NIST for the program structure
  • A named standard, not our preferences

So what is a program then

The baseline protects you. The program proves it.

Comes with managed and co-managed

  • Everything in the six groups above
  • Kept current as things change
  • Reviewed at your regular catch-up
  • No separate line on the invoice

What a program adds on top

  • A formal review of where you stand, in writing
  • A costed roadmap with the risks in order
  • An evidence file kept ready for whoever asks
  • Senior ownership, through a vCISO
  • Tabletop exercises and penetration testing

Most businesses need the baseline and nothing more for a long time. The program becomes worth it when somebody external starts asking you to demonstrate it, or when what you hold makes the answer matter more than usual.

How the program runs

Six parts, in this order.

You do not need all six on day one. You do need to know which one you are missing.

Step 01

Find out where you stand

A review of what you have, what it covers and what it does not. Holistic rather than a tool inventory, because the gaps usually sit between the products rather than inside them. You get a written picture in language you can hand to your board.

Step 02

Get a plan with an order to it

Every review produces a list. The useful part is the sequencing: what genuinely reduces risk first, what can wait a quarter, and what is being sold to you as urgent but is not. Costed, so it can go in a budget rather than an ambition.

Step 03

Fix the technical layer

Multi-factor everywhere it belongs, email filtering tuned to the scams aimed at your industry, device protection, and access reviewed so leavers actually lose access. Implemented in a way your staff will tolerate, because a control people route around is not a control.

Step 04

Train the people

Close to nine in ten breaches trace back to human error, which makes your staff the largest part of your defence whether you have equipped them or not. Short, specific, repeated and measured. More on that below.

Step 05

Rehearse the bad day

A plan nobody has practised falls apart at the worst possible moment. A tabletop exercise puts your key people through a realistic scenario before it is real, and reliably finds the gap nobody knew was there.

Step 06

Keep the evidence current

The file that answers the insurer, the client questionnaire and the board paper. Maintained as things change rather than assembled in a panic, so the next request takes an afternoon instead of a fortnight.

vCISO

A security lead, without hiring a security lead.

Somewhere between fifty staff and a serious compliance obligation, businesses hit a point where security needs somebody senior owning it. Hiring that person is expensive and, for most businesses this size, more capacity than the job actually needs.

A virtual chief information security officer is that role, shared. They set the strategy, own the roadmap, sit in the meetings where risk gets decided, and translate between what your technical people say and what your board needs to hear. Balanced against what the business can actually carry, rather than a maximalist list that gets ignored.

  • Strategy and roadmap ownership
  • Board and client reporting
  • Regulatory and insurer questions
  • Works with your IT team, not over them

The human layer

Training that people actually finish.

Annual compliance training that everyone clicks through in silence changes nothing. These are the parts that do.

Ongoing

Short modules, on your topics

Videos of a few minutes rather than an afternoon, built around the threats your industry actually faces. Progress is tracked, so you know who has done it rather than assuming.

Topics follow recognised guidance rather than whatever is in the news, and the set is tailored to your organisation.

Measured

Phishing simulations

Realistic test emails sent to your staff, with the result used to teach rather than to embarrass. Somewhere between eighty-five and ninety percent of organisations face ongoing phishing attempts, so this is rehearsal for something already happening.

The click rate is the number worth watching. It should fall, and if it does not, the training needs changing rather than repeating.

Live

Sessions where people can ask

Recorded modules cannot answer the question your bookkeeper actually has about the invoice that looked wrong last Tuesday. Live sessions can, and that question is usually the most valuable part of the hour.

Tailored to your user base rather than delivered from a script.

When you are further along

For businesses past the basics.

These are worth doing once the foundations hold. Done too early they produce a long report confirming what you already knew.

Tabletop exercises

Your key people and executives are walked through a realistic breach scenario and asked to respond as they would instinctively. No systems are touched. What gets tested is the plan, and the decision-making.

It reliably finds the gaps: the contact list that is out of date, the decision nobody is sure who makes, the assumption that somebody else was handling notifications. Actions get reviewed, the plan gets rewritten, and it is repeated as people change.

Penetration testing

Controlled, ethical attacks against your systems and applications, from outside and inside, following the NIST standard. It goes past automated scanning to find the root cause of what is genuinely exploitable, with a written account of how each one was used.

Worth doing once your vulnerability scans have stopped returning long lists of critical findings. Before that point, the scan is cheaper and tells you the same thing.

Obligations

The rules that apply to you here.

PIPEDA

Federal private sector privacy law, covering personal information collected in the course of commercial activity. It carries a mandatory breach reporting obligation, which is the part most businesses discover too late.

PIPA, British Columbia

The provincial equivalent for most BC private sector organisations, including a lot of businesses that assume the federal act is the only one that applies to them.

Contractual and sector rules

Often stricter than the legislation. Client contracts, professional body requirements, insurer conditions and GDPR where you hold information about people in Europe. These are usually what forces the deadline.

We are not a law firm and we will not tell you that you are compliant. What we do is build the technical and evidence side so that when your lawyer or your insurer asks, the answers exist.

When somebody asks for proof

Audits and compliance have their own page.

The two sit close together and they are not the same job. Security is the work of being protected. Audit is the work of demonstrating it to an insurer, a client, a funder, a regulator or a board, in the form they have asked for.

Both are included with fully managed and co-managed IT, and audit work is also available on its own if somebody else looks after your systems.

  • Insurer and client questionnaires
  • Funder and grant requirements
  • Board and governance reporting
  • Audits & compliance →

Questions we get asked

The things owners actually want to know.

Pulled from the central library, tagged for this page. All questions and answers →

Is any of this included, or is it all extra?
Cybersecurity

Most of it is included. The protective baseline and the audit and compliance work come with fully managed and co-managed IT, built on the CIS Controls. What is quoted separately is the formal program work: the written review, the roadmap, vCISO time, tabletop exercises and penetration testing.

We are too small to be a target. Is this really necessary?
Cybersecurity

Most attacks are not aimed at anyone. They are automated, they sweep for whatever is exposed, and a twelve-person business is as reachable as a twelve-hundred-person one. The difference is that the larger one has somebody whose job it is to notice.

Is this included in fully managed, or extra?
Cybersecurity

The protective layer is part of fully managed: device protection, multi-factor, email filtering, patching and staff training. A program goes further, and it is the review, the roadmap, the evidence and the senior ownership. Businesses take it on when somebody external starts asking for proof.

Our insurer sent a questionnaire we cannot answer. Can you help?
Cybersecurity

Yes, and it is a common way people arrive here. We work through it question by question, tell you honestly which answers are currently yes, and deal with the ones that are not. Guessing on that form can void the cover you are paying for.

Will security make everything slower for our staff?
Cybersecurity

Badly implemented security does, and then people work around it, which leaves you worse off than before. Done properly most of it is invisible, and the parts that are not get explained rather than imposed. If a control is causing genuine friction, that is a design problem and we will say so.

Do you work with our existing IT team on this?
Cybersecurity

Often, yes. Security is one of the most common reasons businesses take on co-managed IT, because it has grown past what one capable generalist can reasonably hold on their own. We work alongside them, not over them.

Start with where you actually stand.

Half an hour, no charge. Bring the questionnaire that prompted this, if there was one. Worst case you leave knowing which single thing to fix first.

Would rather write?

Send this and we will reply, usually the same business day. No call unless you want one.

  • This field is for validation purposes and should be left unchanged.

Protected by reCAPTCHA.